SV-253821r1099944_rule
V-253821
SRG-APP-000149
TANS-CN-000010
CAT I
10
1. Access the Tanium Server.
2. Log on to the server with an account that has administrative privileges.
3. Run regedit as Administrator.
4. Navigate to HKEY_LOCAL_MACHINE >> SOFTWARE >> WOW6432Node >> Tanium >> Tanium Server.
5. Validate the value for REG_DWORD "ForceSOAPSSLClientCert" is set to "1".
6. Navigate to HKEY_LOCAL_MACHINE >> SOFTWARE >> WOW6432Node >> Tanium >> Tanium Server.
7. Configure the following keys:
REG_SZ "ClientCertificateAuthField"
For example:
X509v3 Subject Alternative Name
REG_SZ "ClientCertificateAuthRegex"
For example-DoD:
.+?Name:\s*?(\S+@[._a-zA-Z0-9]+).*
Note: This regex may vary.
REG_SZ "ClientCertificateAuth"
For example:
C:\Program Files\Tanium\Tanium Server\cac.pem
REG_SZ "TrustedHostList"
For example:
Append 127.0.0.1 (for IPv4) and [::1] (for IPv6)
1. Access the Tanium Server.
2. Log on to the server with an account that has administrative privileges.
3. Run regedit as Administrator.
4. Navigate to HKEY_LOCAL_MACHINE >> SOFTWARE >> WOW6432Node >> Tanium >> Tanium Server.
5. Validate the value for REG_DWORD "ForceSOAPSSLClientCert" is set to "1".
6. Navigate to HKEY_LOCAL_MACHINE >> SOFTWARE >> WOW6432Node >> Tanium >> Tanium Server.
7. Validate the following keys exist and are configured:
REG_SZ "ClientCertificateAuthField"
For example:
X509v3 Subject Alternative Name
REG_SZ "ClientCertificateAuthRegex"
For example-DoD:
.+?Name:\s*?(\S+@[._a-zA-Z0-9]+).*
Note: This regex may vary.
REG_SZ "ClientCertificateAuth"
For example:
C:\Program Files\Tanium\Tanium Server\cac.pem
REG_SZ "TrustedHostList"
For example:
127.0.0.1 (for IPv4) and [::1] (for IPv6)
If the value for REG_DWORD "ForceSOAPSSLClientCert" is not set to "1" and the remaining registry values are not configured, this is a finding.
V-253821
False
TANS-CN-000010
1. Access the Tanium Server.
2. Log on to the server with an account that has administrative privileges.
3. Run regedit as Administrator.
4. Navigate to HKEY_LOCAL_MACHINE >> SOFTWARE >> WOW6432Node >> Tanium >> Tanium Server.
5. Validate the value for REG_DWORD "ForceSOAPSSLClientCert" is set to "1".
6. Navigate to HKEY_LOCAL_MACHINE >> SOFTWARE >> WOW6432Node >> Tanium >> Tanium Server.
7. Validate the following keys exist and are configured:
REG_SZ "ClientCertificateAuthField"
For example:
X509v3 Subject Alternative Name
REG_SZ "ClientCertificateAuthRegex"
For example-DoD:
.+?Name:\s*?(\S+@[._a-zA-Z0-9]+).*
Note: This regex may vary.
REG_SZ "ClientCertificateAuth"
For example:
C:\Program Files\Tanium\Tanium Server\cac.pem
REG_SZ "TrustedHostList"
For example:
127.0.0.1 (for IPv4) and [::1] (for IPv6)
If the value for REG_DWORD "ForceSOAPSSLClientCert" is not set to "1" and the remaining registry values are not configured, this is a finding.
M
5476